VLDB 2026 Research / reviewers in the wild / expert
Frederik Vercauteren
dblp:31/5019
· DBLP profile ↗
65ranked-venue papers
4as first author
17since 2021 · last 2026
0000-0002-7208-9599ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 46 · 3 first-author · 15 since 2021Systems, architecture and hardware · 10 · 1 since 2021Theory of computation · 8 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | sfqt-sfPegasis: Simpler and Faster Effective Class Group Actions
Pierrick Dartois, Jonathan Komada Eriksen, Riccardo Invernizzi, Frederik Vercauteren |
EUROCRYPT (4) | 4 |
| 2026 | Correction to: Actively Secure Setup for SPDZ
Dragos Rotaru, Nigel P. Smart, Titouan Tanguy, Frederik Vercauteren, Tim Wood 0003 |
J. Cryptol. | 4 |
| 2026 | Using Learning with Rounding to Instantiate Post-Quantum Cryptographic AlgorithmsabstractThe Learning with Rounding (LWR) problem, introduced as a deterministic variant of Learning with Errors (LWE), has become a promising foundation for post-quantum cryptography. This Systematization of Knowledge (SoK) article presents a comprehensive survey of the theoretical foundations, algorithmic developments, and practical implementations of LWR-based cryptographic schemes. We introduce LWR within the broader landscape of lattice-based cryptography and post-quantum security, highlighting its advantages such as reduced randomness, improved efficiency, and enhanced side-channel resistance. We explore the evolution of security reductions from LWR to LWE, including recent advances that support practical parameter regimes and address challenges in both bounded and unbounded sample settings. This article systematically reviews existing LWR-based schemes — including Saber, Lizard, Florete, Espada, Sable, and SMAUG — analyzing their design choices, parameter sets, and performance tradeoffs. Furthermore, we examine the impact of LWR on side-channel resistance, failure probabilities, and masking efficiency, demonstrating its suitability for secure and efficient implementations. By consolidating the research spanning theory and practice, this SoK aims at guiding future cryptographic design and standardization efforts leveraging LWR. Andrea Basso 0002, Joppe W. Bos, Jan-Pieter D'Anvers, Angshuman Karmakar, Jose Maria Bermudo Mera, Joost Renes, Sujoy Sinha Roy, Frederik Vercauteren, Peng Wang 0009, Yuewu Wang, Shicong Zhang, Chenxin Zhong |
ACM Trans. Embed. Comput. Syst. | 8 |
| 2025 | sfQlapoti: Simple and Efficient Translation of Quaternion Ideals to Isogenies
Giacomo Borin, Maria Corte-Real Santos, Jonathan Komada Eriksen, Riccardo Invernizzi, Marzio Mula, Sina Schaeffler, Frederik Vercauteren |
ASIACRYPT (4) | 7 |
| 2025 | PEGASIS: Practical Effective Class Group Action using 4-Dimensional Isogenies
Pierrick Dartois, Jonathan Komada Eriksen, Tako Boris Fouotsa, Arthur Herlédan Le Merdy, Riccardo Invernizzi, Damien Robert 0001, Ryan Rueger, Frederik Vercauteren, Benjamin Wesolowski |
CRYPTO (1) | 8 |
| 2025 | Fully Homomorphic Encryption for Cyclotomic Prime Moduli
Robin Geelen, Frederik Vercauteren |
EUROCRYPT (3) | 2 |
| 2025 | PRISM: Simple and Compact Identification and Signatures from Large Prime Degree Isogenies
Andrea Basso 0002, Giacomo Borin, Wouter Castryck, Maria Corte-Real Santos, Riccardo Invernizzi, Antonin Leroux, Luciano Maino, Frederik Vercauteren, Benjamin Wesolowski |
PKC (3) | 8 |
| 2024 | SQIsign2D-East: A New Signature Scheme Using 2-Dimensional Isogenies
Kohei Nakagawa, Hiroshi Onuki, Wouter Castryck, Riccardo Invernizzi, Gioella Lorenzon, Frederik Vercauteren |
ASIACRYPT (3) | 7 |
| 2024 | Generalized Class Group Actions on Oriented Elliptic Curves with Level Structure
Sarah Arpin, Wouter Castryck, Jonathan Komada Eriksen, Gioella Lorenzon, Frederik Vercauteren |
WAIFI | 5 |
| 2023 | A Polynomial Time Attack on Instances of M-SIDH and FESTA
Wouter Castryck, Frederik Vercauteren |
ASIACRYPT (7) | 2 |
| 2023 | Weak Instances of Class Group Action Based Cryptography via Self-pairings
Wouter Castryck, Marc Houben, Simon-Philipp Merz, Marzio Mula, Sam van Buuren, Frederik Vercauteren |
CRYPTO (3) | 6 |
| 2023 | On Polynomial Functions Modulo pe and Faster Bootstrapping for Homomorphic Encryption
Robin Geelen, Ilia Iliashenko, Jiayi Kang, Frederik Vercauteren |
EUROCRYPT (3) | 4 |
| 2023 | Bootstrapping for BGV and BFV Revisited
Robin Geelen, Frederik Vercauteren |
J. Cryptol. | 2 |
| 2022 | Horizontal Racewalking Using Radical Isogenies
Wouter Castryck, Thomas Decru, Marc Houben, Frederik Vercauteren |
ASIACRYPT (2) | 4 |
| 2022 | Breaking the Decisional Diffie-Hellman Problem for Class Group Actions Using Genus Theory: Extended Version
Wouter Castryck, Jana Sotáková, Frederik Vercauteren |
J. Cryptol. | 3 |
| 2022 | Actively Secure Setup for SPDZ
Dragos Rotaru, Nigel P. Smart, Titouan Tanguy, Frederik Vercauteren, Tim Wood 0003 |
J. Cryptol. | 4 |
| 2021 | CSI-RAShi: Distributed Key Generation for CSIDH
Ward Beullens, Lucas Disson, Robi Pedersen, Frederik Vercauteren |
PQCrypto | 4 |
| 2020 | Radical Isogenies
Wouter Castryck, Thomas Decru, Frederik Vercauteren |
ASIACRYPT (2) | 3 |
| 2020 | Breaking the Decisional Diffie-Hellman Problem for Class Group Actions Using Genus Theory
Wouter Castryck, Jana Sotáková, Frederik Vercauteren |
CRYPTO (2) | 3 |
| 2020 | Overdrive2k: Efficient Secure MPC over $\mathbb {Z}_{2^k}$ from Somewhat Homomorphic Encryption
Emmanuela Orsini, Nigel P. Smart, Frederik Vercauteren |
CT-RSA | 3 |
| 2020 | Rational Isogenies from Irrational Endomorphisms
Wouter Castryck, Lorenz Panny, Frederik Vercauteren |
EUROCRYPT (2) | 3 |
| 2019 | CSI-FiSh: Efficient Isogeny Based Signatures Through Class Group Computations
Ward Beullens, Thorsten Kleinjung, Frederik Vercauteren |
ASIACRYPT (1) | 3 |
| 2019 | EPIC: Efficient Private Image Classification (or: Learning from the Masters)
Eleftheria Makri, Dragos Rotaru, Nigel P. Smart, Frederik Vercauteren |
CT-RSA | 4 |
| 2019 | Pushing the speed limit of constant-time discrete Gaussian sampling. A case study on the Falcon signature schemeabstractSampling from a discrete Gaussian distribution has applications in lattice-based post-quantum cryptography. Several efficient solutions have been proposed in recent years. However, making a Gaussian sampler secure against timing attacks turned out to be a challenging research problem. In this work, we present a toolchain to instantiate an efficient constant-time discrete Gaussian sampler of arbitrary standard deviation and precision. We observe an interesting property of the mapping from input random bit strings to samples during a Knuth-Yao sampling algorithm and propose an efficient way of minimizing the Boolean expressions for the mapping. Our minimization approach results in up to 37% faster discrete Gaussian sampling compared to the previous work. Finally, we apply our optimized and secure Gaussian sampler in the lattice-based digital signature algorithm Falcon, which is a NIST submission, and provide experimental evidence that the overall performance of the signing algorithm degrades by at most 33% only due to the additional overhead of 'constant-time' sampling, including the 60% overhead of random number generation. Breaking a general belief, our results indirectly show that the use of discrete Gaussian samples in digital signature algorithms would be beneficial. Angshuman Karmakar, Sujoy Sinha Roy, Frederik Vercauteren, Ingrid Verbauwhede |
DAC | 3 |
| 2019 | FPGA-Based High-Performance Parallel Architecture for Homomorphic Computing on Encrypted DataabstractHomomorphic encryption is a tool that enables computation on encrypted data and thus has applications in privacy-preserving cloud computing. Though conceptually amazing, implementation of homomorphic encryption is very challenging and typically software implementations on general purpose computers are extremely slow. In this paper we present our year long effort to design a domain specific architecture in a heterogeneous Arm+FPGA platform to accelerate homomorphic computing on encrypted data. We design a custom co-processor for the computationally expensive operations of the well-known Fan-Vercauteren (FV) homomorphic encryption scheme on the FPGA, and make the Arm processor a server for executing different homomorphic applications in the cloud, using this FPGA-based co-processor. We use the most recent arithmetic and algorithmic optimization techniques and perform designspace exploration on different levels of the implementation hierarchy. In particular we apply circuit-level and block-level pipeline strategies to boost the clock frequency and increase the throughput respectively. To reduce computation latency, we use parallel processing at all levels. Starting from the highly optimized building blocks, we gradually build our multi-core multi-processor architecture for computing. We implemented and tested our optimized domain specific programmable architecture on a single Xilinx Zynq UltraScale+ MPSoC ZCU102 Evaluation Kit. At 200 MHz FPGA-clock, our implementation achieves over 13x speedup with respect to a highly optimized software implementation of the FV homomorphic encryption scheme on an Intel i5 processor running at 1.8 GHz. Sujoy Sinha Roy, Furkan Turan, Kimmo Järvinen 0001, Frederik Vercauteren, Ingrid Verbauwhede |
HPCA | 4 |
| 2019 | The Impact of Error Dependencies on Ring/Mod-LWE/LWR Based Schemes
Jan-Pieter D'Anvers, Frederik Vercauteren, Ingrid Verbauwhede |
PQCrypto | 2 |
| 2019 | Faster SeaSign Signatures Through Improved Rejection Sampling
Thomas Decru, Lorenz Panny, Frederik Vercauteren |
PQCrypto | 3 |
| 2018 | Homomorphic SIM ^2 D Operations: Single Instruction Much More Data
Wouter Castryck, Ilia Iliashenko, Frederik Vercauteren |
EUROCRYPT (1) | 3 |
| 2018 | Towards practical privacy-preserving genome-wide association studyabstractThe deployment of Genome-wide association studies (GWASs) requires genomic information of a large population to produce reliable results. This raises significant privacy concerns, making people hesitate to contribute their genetic information to such studies. We propose two provably secure solutions to address this challenge: (1) a somewhat homomorphic encryption (HE) approach, and (2) a secure multiparty computation (MPC) approach. Unlike previous work, our approach does not rely on adding noise to the input data, nor does it reveal any information about the patients. Our protocols aim to prevent data breaches by calculating the χ 2 statistic in a privacy-preserving manner, without revealing any information other than whether the statistic is significant or not. Specifically, our protocols compute the χ 2 statistic, but only return a yes/no answer, indicating significance. By not revealing the statistic value itself but only the significance, our approach thwarts attacks exploiting statistic values. We significantly increased the efficiency of our HE protocols by introducing a new masking technique to perform the secure comparison that is necessary for determining significance. We show that full-scale privacy-preserving GWAS is practical, as long as the statistics can be computed by low degree polynomials. Our implementations demonstrated that both approaches are efficient. The secure multiparty computation technique completes its execution in approximately 2 ms for data contributed by one million subjects. Charlotte Bonte, Eleftheria Makri, Amin Ardeshirdavani, Jaak Simm, Yves Moreau, Frederik Vercauteren |
BMC Bioinform. | 6 |
| 2018 | Constant-Time Discrete Gaussian SamplingabstractSampling from a discrete Gaussian distribution is an indispensable part of lattice-based cryptography. Several recent works have shown that the timing leakage from a non-constant-time implementation of the discrete Gaussian sampling algorithm could be exploited to recover the secret. In this paper, we propose a constant-time implementation of the Knuth-Yao random walk algorithm for performing constant-time discrete Gaussian sampling. Since the random walk is dictated by a set of input random bits, we can express the generated sample as a function of the input random bits. Hence, our constant-time implementation expresses the unique mapping of the input random-bits to the output sample-bits as a Boolean expression of the random-bits. We use bit-slicing to generate multiple samples in batches and thus increase the throughput of our constant-time sampling manifold. Our experiments on an Intel i7-Broadwell processor show that our method can be as much as 2.4 times faster than the constant-time implementation of cumulative distribution table based sampling and consumes exponentially less memory than the Knuth-Yao algorithm with shuffling for a similar level of security. Angshuman Karmakar, Sujoy Sinha Roy, Oscar Reparaz, Frederik Vercauteren, Ingrid Verbauwhede |
IEEE Trans. Computers | 4 |
| 2018 | HEPCloud: An FPGA-Based Multicore Processor for FV Somewhat Homomorphic Function EvaluationabstractIn this paper, we present an FPGA based hardware accelerator ‘$\mathsf{HEPCloud}$’ for homomorphic evaluations of medium depth functions which has applications in cloud computing. Our$\mathsf{HEPCloud}$architecture supports the polynomial ring based homomorphic encryption scheme FV for a ring-LWE parameter set of dimension$2^{15}$, modulus size 1,228-bit, and a standard deviation 50. This parameter-set offers a multiplicative depth 36 and at least 85 bit security. The processor of$\mathsf{HEPCloud}$is composed of multiple parallel cores. To achieve fast computation time for such a large parameter-set, various optimizations in both algorithm and architecture levels are performed. For fast polynomial multiplications, we use CRT with NTT and achieve two dimensional parallelism in$\mathsf{HEPCloud}$. We optimize the BRAM access, use a fast Barrett like polynomial reduction method, optimize the cost of CRT, and design a fast divide-and-round unit. Beside parallel processing, we apply pipelining strategy in several of the sequential building blocks to reduce the impact of sequential computations. Finally, we implement$\mathsf{HEPCloud}$on a medium-size Xilinx Virtex 6 FPGA board ML605 board and measure its on-board performance. To store the ciphertexts during a homomorphic function evaluation, we use the large DDR3 memory of the ML605 board. Our FPGA-based implementation of$\mathsf{HEPCloud}$computes a homomorphic multiplication in 26.67 s, of which the actual computation takes only 3.36 s and the rest is spent for off-chip memory access. It requires about 37,551 s to evaluate the SIMON-64/128 block cipher, but the per-block timing is only about 18 s because$\mathsf{HEPCloud}$processes 2,048 blocks simultaneously. The results show that FPGA-based acceleration of homomorphic function evaluations is feasible, but fast memory interface is crucial for the performance. Sujoy Sinha Roy, Kimmo Järvinen 0001, Jo Vliegen, Frederik Vercauteren, Ingrid Verbauwhede |
IEEE Trans. Computers | 4 |
| 2017 | Faster Homomorphic Function Evaluation Using Non-integral Base Encoding
Charlotte Bonte, Carl Bootland, Joppe W. Bos, Wouter Castryck, Ilia Iliashenko, Frederik Vercauteren |
CHES | 6 |
| 2017 | Hardware Assisted Fully Homomorphic Function Evaluation and Encrypted SearchabstractIn this paper we propose a scheme to perform homomorphic evaluations of arbitrary depth with the assistance of a special module recryption box. Existing somewhat homomorphic encryption schemes can only perform homomorphic operations until the noise in the ciphertexts reaches a critical bound depending on the parameters of the homomorphic encryption scheme. The classical approach of bootstrapping also allows for arbitrary depth evaluations, but has a detrimental impact on the size of the parameters, making the whole setup inefficient. We describe two different instantiations of our recryption box for assisting homomorphic evaluations of arbitrary depth. The recryption box refreshes the ciphertexts by lowering the inherent noise and can be used with any instantiation of the parameters, i.e. there is no minimum size unlike bootstrapping. To demonstrate the practicality of the proposal, we design the recryption box on a Xilinx Virtex 6 FPGA board ML605 to support the FV somewhat homomorphic encryption scheme. The recryption box requires 0.43 ms to refresh one ciphertext. Further, we use this recryption box to boost the performance of encrypted search operation. On a 40 core Intel server, we can perform encrypted search in a table of 216 entries in around 20 seconds. This is roughly 20 times faster than the implementation without recryption box. Sujoy Sinha Roy, Frederik Vercauteren, Jo Vliegen, Ingrid Verbauwhede |
IEEE Trans. Computers | 2 |
| 2016 | Provably Weak Instances of Ring-LWE Revisited
Wouter Castryck, Ilia Iliashenko, Frederik Vercauteren |
EUROCRYPT (1) | 3 |
| 2016 | Additively Homomorphic Ring-LWE Masking
Oscar Reparaz, Ruan de Clercq, Sujoy Sinha Roy, Frederik Vercauteren, Ingrid Verbauwhede |
PQCrypto | 4 |
| 2016 | Efficient Finite Field Multiplication for Isogeny Based Post Quantum Cryptography
Angshuman Karmakar, Sujoy Sinha Roy, Frederik Vercauteren, Ingrid Verbauwhede |
WAIFI | 3 |
| 2015 | A Masked Ring-LWE Implementation
Oscar Reparaz, Sujoy Sinha Roy, Frederik Vercauteren, Ingrid Verbauwhede |
CHES | 3 |
| 2015 | Modular Hardware Architecture for Somewhat Homomorphic Function Evaluation
Sujoy Sinha Roy, Kimmo Järvinen 0001, Frederik Vercauteren, Vassil S. Dimitrov, Ingrid Verbauwhede |
CHES | 3 |
| 2015 | Efficient software implementation of ring-LWE encryption
Ruan de Clercq, Sujoy Sinha Roy, Frederik Vercauteren, Ingrid Verbauwhede |
DATE | 3 |
| 2014 | Compact Ring-LWE Cryptoprocessor
Sujoy Sinha Roy, Frederik Vercauteren, Nele Mentens, Donald Donglong Chen, Ingrid Verbauwhede |
CHES | 2 |
| 2014 | Fully homomorphic SIMD operations
Nigel P. Smart, Frederik Vercauteren |
Des. Codes Cryptogr. | 2 |
| 2013 | High Precision Discrete Gaussian Sampling on FPGAs
Sujoy Sinha Roy, Frederik Vercauteren, Ingrid Verbauwhede |
Selected Areas in Cryptography | 2 |
| 2012 | A cross-protocol attack on the TLS protocolabstractThis paper describes a cross-protocol attack on all versions of TLS; it can be seen as an extension of the Wagner and Schneier attack on SSL 3.0. The attack presents valid explicit elliptic curve Diffie-Hellman parameters signed by a server to a client that incorrectly interprets these parameters as valid plain Diffie-Hellman parameters. Our attack enables an adversary to successfully impersonate a server to a random client after obtaining 240 signed elliptic curve keys from the original server. While attacking a specific client is improbable due to the high number of signed keys required during the lifetime of one TLS handshake, it is not completely unrealistic for a setting where the server has high computational power and the attacker contents itself with recovering one out of many session keys. We remark that popular open-source server implementations are not susceptible to this attack, since they typically do not support the explicit curve option. Finally we propose a fix that renders the protocol immune to this family of cross-protocol attacks. Nikos Mavrogiannopoulos, Frederik Vercauteren, Vesselin Velichkov, Bart Preneel |
CCS | 2 |
| 2012 | Practical Realisation and Elimination of an ECC-Related Software Bug Attack
Billy Bob Brumley, Manuel Barbosa, Dan Page, Frederik Vercauteren |
CT-RSA | 4 |
| 2012 | Efficient Hardware Implementation of Fp-Arithmetic for Pairing-Friendly CurvesabstractThis paper describes a new method to speed up {\hbox{\rlap{I}\kern 2.0pt{\hbox{F}}}}_p-arithmetic in hardware for pairing-friendly curves, such as the well-known Barreto-Naehrig (BN) curves. We explore the characteristics of the modulus defined by these curves and choose curve parameters such that {\hbox{\rlap{I}\kern 2.0pt{\hbox{F}}}}_p multiplication becomes more efficient. The proposed algorithm uses Montgomery reduction in a polynomial ring combined with a coefficient reduction phase using a pseudo-Mersenne number. As an application, we show that the performance of pairings on BN curves in hardware can be significantly improved, resulting in a factor 2.5 speedup compared with state-of-the-art hardware implementations. Junfeng Fan, Frederik Vercauteren, Ingrid Verbauwhede |
IEEE Trans. Computers | 2 |
| 2011 | To Infinity and Beyond: Combined Attack on ECC Using Points of Low Order
Junfeng Fan, Benedikt Gierlichs, Frederik Vercauteren |
CHES | 3 |
| 2011 | A New RFID Privacy Model
Jens Hermans, Andreas Pashalidis, Frederik Vercauteren, Bart Preneel |
ESORICS | 3 |
| 2011 | Toric forms of elliptic curves and their arithmetic
Wouter Castryck, Frederik Vercauteren |
J. Symb. Comput. | 2 |
| 2010 | Speed Records for NTRU
Jens Hermans, Frederik Vercauteren, Bart Preneel |
CT-RSA | 2 |
| 2010 | Speeding Up Bipartite Modular Multiplication
Miroslav Knezevic, Frederik Vercauteren, Ingrid Verbauwhede |
WAIFI | 2 |
| 2010 | Faster Interleaved Modular Multiplication Based on Barrett and Montgomery Reduction MethodsabstractIEEE Abstract—This paper proposes two improved interleaved modular multiplication algorithms based on Barrett and Montgomery modular reduction. The algorithms are simple and especially suitable for hardware implementations. Four large sets of moduli for which the proposed methods apply are given and analyzed from a security point of view. By considering state-of-the-art attacks on public-key cryptosystems, we show that the proposed sets are safe to use, in practice, for both elliptic curve cryptography and RSA cryptosystems. We propose a hardware architecture for the modular multiplier that is based on our methods. The results show that concerning the speed, our proposed architecture outperforms the modular multiplier based on standard modular multiplication by more than 50 percent. Additionally, our design consumes less area compared to the standard solutions. Index Terms—Modular multiplication, Barrett reduction, Montgomery reduction, public-key cryptography. Miroslav Knezevic, Frederik Vercauteren, Ingrid Verbauwhede |
IEEE Trans. Computers | 2 |
| 2010 | Optimal pairingsabstractIn this paper, we introduce the concept of an optimal pairing, which by definition can be computed using onlylog2r/¿(k) basic Miller iterations, withrthe order of the groups involved andkthe embedding degree. We describe an algorithm to construct optimal ate pairings on all parametrized families of pairing friendly elliptic curves. Finally, we conjecture that any nondegenerate pairing on an elliptic curve without efficiently computable endomorphisms different from powers of Frobenius requires at leastlog2r/¿(k) basic Miller iterations. Frederik Vercauteren |
IEEE Trans. Inf. Theory | 1 |
| 2009 | Faster -Arithmetic for Cryptographic Pairings on Barreto-Naehrig Curves
Junfeng Fan, Frederik Vercauteren, Ingrid Verbauwhede |
CHES | 2 |
| 2008 | The Hidden Root Problem
Frederik Vercauteren |
Pairing | 1 |
| 2008 | Aspects of Pairing InversionabstractIn this paper, we discuss some applications of the pairing inversion problem and outline some potential approaches for solving it. Our analysis of these approaches gives further evidence that pairing inversion is a difficult problem. Steven D. Galbraith, Florian Hess, Frederik Vercauteren |
IEEE Trans. Inf. Theory | 3 |
| 2007 | Ate Pairing on Hyperelliptic Curves
Robert Granger, Florian Hess, Roger Oyono, Nicolas Thériault, Frederik Vercauteren |
EUROCRYPT | 5 |
| 2007 | Hyperelliptic Pairings
Steven D. Galbraith, Florian Hess, Frederik Vercauteren |
Pairing | 3 |
| 2007 | On computable isomorphisms in efficient asymmetric pairing-based systems
Nigel P. Smart, Frederik Vercauteren |
Discret. Appl. Math. | 2 |
| 2006 | The Number Field Sieve in the Medium Prime Case
Antoine Joux, Reynald Lercier, Nigel P. Smart, Frederik Vercauteren |
CRYPTO | 4 |
| 2006 | An Extension of Kedlaya's Algorithm to Hyperelliptic Curves in Characteristic 2
Jan Denef, Frederik Vercauteren |
J. Cryptol. | 2 |
| 2006 | A Fault Attack on Pairing-Based CryptographyabstractCurrent fault attacks against public key cryptography focus on traditional schemes, such as RSA and ECC, and, to a lesser extent, on primitives such as XTR. However, bilinear maps, or pairings, have presented theorists with a new and increasingly popular way of constructing cryptographic protocols. Most notably, this has resulted in efficient methods for identity based encryption (IBE). Since identity-based cryptography seems an ideal partner for identity aware devices such as smart-cards, in this paper, we examine the security of concrete pairing instantiations in terms of fault attack Dan Page, Frederik Vercauteren |
IEEE Trans. Computers | 2 |
| 2006 | The Eta Pairing RevisitedabstractIn this paper, we simplify and extend the Eta pairing, originally discovered in the setting of supersingular curves by Barreto , to ordinary curves. Furthermore, we show that by swapping the arguments of the Eta pairing, one obtains a very efficient algorithm resulting in a speed-up of a factor of around six over the usual Tate pairing, in the case of curves that have large security parameters, complex multiplication by an order of Qopf (radic-3), and when the trace of Frobenius is chosen to be suitably small. Other, more minor savings are obtained for more general curves Florian Hess, Nigel P. Smart, Frederik Vercauteren |
IEEE Trans. Inf. Theory | 3 |
| 2005 | On the Discrete Logarithm Problem on Algebraic Tori
Robert Granger, Frederik Vercauteren |
CRYPTO | 2 |
| 2002 | Computing Zeta Functions of Hyperelliptic Curves over Finite Fields of Characteristic 2
Frederik Vercauteren |
CRYPTO | 1 |
| 2001 | A Memory Efficient Version of Satoh's Algorithm
Frederik Vercauteren, Bart Preneel, Joos Vandewalle |
EUROCRYPT | 1 |